Infosecurity News

Plex Suffers Data Breach, Warns Users to Reset Passwords
The company said it discovered suspicious activity on one of its databases on Tuesday

War in Ukraine Has Pushed Two-Thirds of Businesses to Change Cyber Strategy
The use of machine identity tools is growing in state-sponsored cyber-attacks

VMware Fixes Privilege Escalation Vulnerabilities in VMware Tools
The flaw reportedly impacted the software on both Windows and Linux systems

IoT Vulnerability Disclosures Up 57% in Six Months, Claroty Reveals
The research also found that vendor self-disclosures increased by 69%

Facebook Bug Causes Users’ Feeds to Be Spammed
Users’ feeds were spammed with posts from strangers on the pages of celebrities

Ransomware Surges to 1.2 Million Attacks Per Month
French hospital is the latest to be hit

EU Outlines Critical Cyber Response to Ukraine War
Agencies team up to police borders and mitigate Russian cyber-threats

US Healthcare Sector Breaches 342m+ Records Since 2009
Biggest year so far was 2020

NCSC Shares Guidance to Help Secure Large Construction Projects
The guide includes input from firms with experience in joint ventures, including major infrastructure contracts such as HS2 and Crossrail

Ex-Security Chief Accuses Twitter of Cybersecurity Negligence
Peiter Zatko admitted that he “reasonably feared Twitter could suffer an Equifax-level hack”

CISA Adds Palo Alto Networks' PAN-OS Vulnerability to Catalog
The flaw would allow a network-based unauthenticated threat actor to perform DoS attacks

Air-Gap Attack Exploits Gyroscope Ultrasonic Covert Channel to Leak Data
Gairoscope is a covert ultrasonic channel that does not require a microphone on the receiving side

Counterfeit Android Devices Revealed to Contain Backdoor Designed to Hack WhatsApp
At least four different smartphones affected: ‘P48pro’, ‘radmi note 8’, ‘Note30u’ and ‘Mate40’

Media Firms Twice as Vulnerable as Cross-Sector Average
Nearly a third have internet-facing bugs, says BlueVoyant

Configuration Errors to Blame for 80% of Ransomware
Microsoft urges better attack surface management

FBI: Beware Residential IPs Hiding Credential Stuffing
Feds warn of various tactics hackers use to hijack accounts

CEO of Blacklisted Israeli Spyware Maker NSO Steps Down
The resignation of CEO Shalev Hulio will see COO Yaron Shohat take the helm

Escanor RAT Malware Deployed Via Microsoft Office and PDF Documents
The malware was first released for sale on January 26, 2022 as an HVNC implant, but later evolved

Threat Actor Deploys Raven Storm Tool to Perform DDoS Attacks
The malware is reportedly capable of server takedown, Wi-Fi attacks and application layer attacks

DDoS Protection Weaponized to Deliver RATs
New campaign disguised as fake Cloudflare pop-up



